CVE-2025-66547
- EPSS 0.01%
- Veröffentlicht 05.12.2025 16:32:17
- Zuletzt bearbeitet 09.12.2025 16:31:38
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-privileged users can modify tags on files they should not have access to via bulk tagging. This vulnerability is fixed in 31.0.1.
CVE-2025-66512
- EPSS 0.02%
- Veröffentlicht 05.12.2025 16:22:50
- Zuletzt bearbeitet 09.12.2025 16:38:19
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and 32.0.3, a missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to ...
CVE-2025-47794
- EPSS 0.02%
- Veröffentlicht 16.05.2025 14:35:25
- Zuletzt bearbeitet 30.09.2025 19:37:40
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user sys...
CVE-2025-47793
- EPSS 0.05%
- Veröffentlicht 16.05.2025 14:31:50
- Zuletzt bearbeitet 08.09.2025 21:54:14
Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and 28.0.1, Nextcloud Enterprise Server ...
CVE-2025-47791
- EPSS 0.04%
- Veröffentlicht 16.05.2025 14:09:27
- Zuletzt bearbeitet 19.09.2025 17:41:47
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 28.0.13, 29.0.10, and 30.0.3 and Nextcloud Enterprise Server prior to 28.0.13, 29.0.10, and 30.0.3, a currently unused endpoint to verify a share recipient was not ...
CVE-2025-47790
- EPSS 0.02%
- Veröffentlicht 16.05.2025 14:02:57
- Zuletzt bearbeitet 30.09.2025 19:59:50
Nextcloud Server is a self hosted personal cloud system. Nextcloud Server prior to 29.0.15, 30.0.9, and 31.0.3 and Nextcloud Enterprise Server prior to 26.0.13.15, 27.1.11.15, 28.0.14.6, 29.0.15, 30.0.9, and 31.0.3 have a bug with session handling. T...
CVE-2024-52513
- EPSS 0.1%
- Veröffentlicht 15.11.2024 18:15:30
- Zuletzt bearbeitet 01.10.2025 18:04:28
Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to download attachments that are referenced in Text files without providing the password. It is recom...
CVE-2024-52514
- EPSS 0.05%
- Veröffentlicht 15.11.2024 18:15:30
- Zuletzt bearbeitet 01.10.2025 17:49:30
Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access control, the user would still be able to copy the intermediate folder inside Nextcloud allowing them to af...
CVE-2024-52525
- EPSS 0.11%
- Veröffentlicht 15.11.2024 17:15:23
- Zuletzt bearbeitet 23.01.2025 14:33:48
Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would...
CVE-2024-52520
- EPSS 0.38%
- Veröffentlicht 15.11.2024 17:15:22
- Zuletzt bearbeitet 05.09.2025 00:00:50
Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Se...